Description
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin All-In-One Security (AIOS)-Security and Firewall version 5.1.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.5 or latest
References
Related Vulnerabilities
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.17)
Plone CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-33511)
Joomla! Core Remote Code Execution (1.5.0 - 3.4.5)
WordPress Plugin Wbcom Designs-BuddyPress Group Reviews Security Bypass (2.8.3)
Plone CMS Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-28736)